Job Description
The role is responsible for protecting the organization’s information assets by defining the security strategy and ensuring effective management of the risks and threats that may impact the organization. The Head of Information Security provides leadership in establishing a secure and resilient operating environment, promotes a strong security culture, and ensures compliance with applicable regulatory and governance requirements. As a senior executive, the Head of Information Security advises executive management on security-related matters and ensures that security objectives remain aligned with business priorities and organizational goals.
Responsibilities
Develop a deep understanding of the organization's business objectives, operating environment and critical information assets. Define the information security strategy and ensure alignment with corporate objectives. Establish and maintain the organization’s security governance framework. Define and oversee security policies and strategic security initiatives. Ensure that security risks are identified, assessed and managed appropriately. Promote security awareness and foster a culture of accountability across the organization. Provide executive oversight during significant security incidents and crisis situations. Ensure compliance with applicable regulations, standards and governance requirements. Periodically assess the effectiveness of the organization’s security capabilities and improvement initiatives. Define executive metrics and performance indicators to measure security effectiveness and risk exposure. Report regularly to executive leadership on the organization’s security posture, key risks and strategic priorities. Coordinate security-related activities with business leaders and key corporate stakeholders. Act as the primary point of alignment between business priorities and security objectives. Oversee third-party security risks and ensure appropriate governance of external service providers. Define strategic investment priorities and manage the security budget to support business objectives. Chair or sponsor the organization’s security governance committee.
Qualifications
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field from a recognized university. A relevant Master’s degree is an advantage.
Qatari National (mandatory)
Minimum 10+ years of relevant experience in information security, cyber risk management, or related leadership roles.
Minimum 3–5 years of experience managing similar work – leading an information security / cybersecurity function or advising at executive level. Experience defining an information security strategy aligned with business objectives, and managing security risks and threats end-to-end. Demonstrated experience with Qatar’s regulatory frameworks (NCSA, NIA, CIIP, PDPPL). Proven ability to engage and influence executive management, boards and key stakeholders. Experience leading multidisciplinary teams and managing complex, high-pressure situations and incidents. Relevant certifications such as CISSP, CISM, CISA, CRISC, or equivalent are desirable Strong understanding of security, risk, governance and regulatory frameworks Ability to translate security requirements into business priorities and strategic initiatives Ability to promote and foster a security-aware culture across the organisation Security incident and crisis leadership
Technical
Security strategy & governance Risk & threat management Regulatory & compliance (NCSA, NIA, CIIP, PDPPL) Security architecture & resilience Incident & crisis management Third-party / vendor security governance
Behavioral
Strategic & critical thinking Executive influence & stakeholder management Leadership & team management Result orientation Excellent communication Integrity & discretion
وصف الوظيفة
المهمة هي حماية أصول معلومات المؤسسة من خلال تحديد استراتيجية الأمن وإدارة المخاطر والتهديدات التي قد تؤثر على المنظمة بشكل فعال. يوفر رئيس أمن المعلومات قيادة في إنشاء بيئة تشغيل آمنة ومرنة، ويروج لثقافة أمن قوية، ويضمن الامتثال للمتطلبات التنظيمية والحوكمة المعمول بها. وبصفته قائدًا تنفيذيًا، يُقدم رئيس أمن المعلومات المشورة للإدارة التنفيذية في المسائل المتعلقة بالأمن ويضمن أن تبقى أهداف الأمن متوافقة مع أولويات الأعمال وأهداف المؤسسة.
المسؤوليات
فهم عميق لأهداف أعمال المنظمة وبيئة التشغيل والأصول المعلوماتية الحيوية. تعريف استراتيجية الأمن المعلوماتي وضمان التوافق مع أهداف الشركة. إنشاء وصيانة إطار حوكمة الأمن للمؤسسة. تعريف والإشراف على سياسات الأمن والمبادرات الأمنية الاستراتيجية. التأكد من تحديد مخاطر الأمن وتقييمها وإدارتها بشكل مناسب. تعزيز الوعي الأمني وت fostering ثقافة المساءلة عبر المؤسسة. تقديم إشراف تنفيذي أثناء الحوادث الأمنية الكبرى ووضع الأزمات. ضمان الامتثال للوائح والمعايير وأحكام الحوكمة المعمول بها. تقييم فعالية قدرات الأمن ومبادرات التحسين بشكل دوري. تعريف مقاييس تنفيذية ومؤشرات أداء لقياس فاعلية الأمن وخطر التعرض. إعداد تقارير دورية لقيادة التنفيذ عن وضع الأمن في المؤسسة والمخاطر الرئيسية الأولويات الاستراتيجية. تنسيق الأنشطة المتعلقة بالأمن مع قادة الأعمال وأصحاب المصلحة الرئيسيين في الشركة. العمل كنقطة المحاذاة الأساسية بين أولويات العمل وأهداف الأمن. الإشراف على مخاطر الأمن الطرف الثالث وضمان الحوكمة الملائمة لمقدمي الخدمات الخارجيين. تحديد أولويات الاستثمار الاستراتيجي وإدارة ميزانية الأمن لدعم أهداف العمل. رئاسة أو رعاية لجنة حوكمة الأمن في المؤسسة.
المؤهلات
درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني، أو مجال ذي صلة من جامعة معترف بها. درجة الماجستير ذات صلة تعتبر ميزة.
المواطن القطري (إلزامي)
حد أدنى 10+ سنوات من الخبرة ذات الصلة في الأمن المعلوماتي، إدارة مخاطر السيبراني، أو أدوار قيادية ذات صلة.
حد أدنى 3–5 سنوات من الخبرة في إدارة عمل مماثل – قيادة وظيفة الأمن المعلوماتي / الأمن السيبراني أو تقديم المشورة على المستوى التنفيذي. خبرة في تعريف استراتيجية أمن معلوماتي متوافقة مع أهداف الأعمال، وإدارة مخاطر وتهديدات الأمن من البداية للنهاية. خبرة مثبتة في أطر تنظيمية قطرية (NCSA، NIA، CIIP، PDPPL). قدرة مثبتة على المشاركة والتأثير في الإدارة التنفيذية، العروض والجهات المعنية الرئيسية. خبرة في قيادة فرق متعددة التخصصات وإدارة مواقف وحوادث عالية الضغط ومعقدة. شهادات ذات صلة مثل CISSP، CISM، CISA، CRISC، أو ما يعادلها مطلوبة. فهم قوي للأمن، والمخاطر، والحوكمة، والإطارات التنظيمية. القدرة على ترجمة متطلبات الأمن إلى أولويات أعمال ومبادرات استراتيجية. القدرة على تعزيز ونشر ثقافة الوعي الأمني عبر المؤسسة. قيادة حوادث الأمن والأزمات
التقني
استراتيجية الأمن والحوكمة إدارة المخاطر والتهديدات التنظيم والامتثال (NCSA، NIA، CIIP، PDPPL) هندسة الأمن والمرونة إدارة الحوادث والأزمات حوكمة الأمن لدى الطرف الثالث/المورّدين
السلوكي
التفكير الاستراتيجي والنقدي التأثير التنفيذي وإدارة صاحب المصلحة القيادة وإدارة الفريق توجيه النتائج الاتصالات الفعالة النزاهة والحرص